THREAT OPS › Threat News › [GHSA] GHSA-j5jq-cr68-v2xx (high) — Winter: Authenticated backend users can bypass Users controller permission checks
[GHSA] GHSA-j5jq-cr68-v2xx (high) — Winter: Authenticated backend users can bypass Users controller permission checks
GHSA-j5jq-cr68-v2xx Severity: high CVE: CVE-2026-35445
Winter: Authenticated backend users can bypass Users controller permission checks
### Impact
Affected versions of Winter CMS did not validate the handler name submitted through the form postback mechanism (`_handler` POST field) in the same way as AJAX requests (`X_WINTER_REQUEST_HANDLER` header). The AJAX path validates that handler names
Indicators of compromise
- CVE-2026-35445cve
Original source: https://github.com/advisories/GHSA-j5jq-cr68-v2xx